AWS Security Hub

Automate AWS security checks and centralize security alerts

Use AWS Security Hub to automate security best practice checks, aggregate security alerts into a single place and format, and understand your overall security posture across all of your AWS accounts.","id":"collection-text-media#overview-prod-overview-awssecurityhub","mediaPosition":"right","mediaAltText":"Introduction to AWS Security Hub "},"metadata":{"tags":[{"id":"GLOBAL#pattern#overview","name":"Overview","namespaceId":"GLOBAL#pattern","description":"Overview","metadata":{}},{"id":"GLOBAL#product#security-hub","name":"AWS Security Hub","namespaceId":"GLOBAL#product","description":"AWS Security Hub","metadata":{}}]}}]},"metadata":{"auth":{},"pagination":{"empty":false,"present":true},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security-hub/"},"environment":{"stage":"prod","region":"us-east-1"},"sdkVersion":"1.0.120"},"refMap":{"manifest.js":"47864e0370","rt-text-media-collection.js":"2ff4ed8f57","rt-text-media-collection.css":"4cb26045f9","rt-text-media-collection.css.js":"fb8a6a6554","rt-text-media-collection.rtl.css":"f31a3175e6","rt-text-media-collection.rtl.css.js":"77897591ba"},"settings":{"templateMappings":{"hyperlinkText":"hyperlinkText","hyperlinkUrl":"hyperlinkUrl","heading":"heading","mediaAltText":"mediaAltText","mediaPosition":"mediaPosition","mediaUrl":"mediaUrl","subheader":"subheader","bodyContent":"bodyContent","videoOverlayTitle":"videoOverlayTitle","videoThumbnailUrl":"videoThumbnailUrl","videoPlayButtonText":"videoPlayButtonText","dark":"dark"}}}

Introduction to AWS Security Hub

Use AWS Security Hub to automate security best practice checks, aggregate security alerts into a single place and format, and understand your overall security posture across all of your AWS accounts.

Benefits of Security Hub

Detect deviations from security best practices with a single click.
Automatically aggregate security findings in a standardized data format from AWS and partner services.
Accelerate mean time to resolution with automated response and remediation actions.
Visualize the security posture of your AWS-based applications.

Reduce your risk with automated checks based on a collection of security controls curated by experts and simplify compliance management with built in mapping capabilities for common frameworks like CIS, PCI DSS, and more."},"metadata":{"tags":[{"id":"GLOBAL#product#security-hub","name":"AWS Security Hub","namespaceId":"GLOBAL#product","description":"AWS Security Hub","metadata":{}},{"id":"GLOBAL#pattern#use-cases","name":"Use Cases","namespaceId":"GLOBAL#pattern","description":"Use Cases","metadata":{}}]}},{"fields":{"useCaseTitle":"Initiate Security Orchestration, Automation, and Response (SOAR) workflows","id":"product-use-cases#usecase-2-prod-overview-awssecurityhub","customSortOrder":"2","useCaseSummary":"

Automatically enrich findings, remediate them, or send them to ticketing systems with Security Hub’s integration with Amazon EventBridge."},"metadata":{"tags":[{"id":"GLOBAL#product#security-hub","name":"AWS Security Hub","namespaceId":"GLOBAL#product","description":"AWS Security Hub","metadata":{}},{"id":"GLOBAL#pattern#use-cases","name":"Use Cases","namespaceId":"GLOBAL#pattern","description":"Use Cases","metadata":{}}]}},{"fields":{"useCaseTitle":"Save time and money by simplifying integrations","id":"product-use-cases#usecase-3-prod-overview-awssecurityhub","customSortOrder":"3","useCaseSummary":"

Simplify and streamline data ingestion into your Security Information and Event Management (SIEM), ticketing, and other tools by consolidating the integrations between AWS services and your downstream tooling and by normalizing your findings."},"metadata":{"tags":[{"id":"GLOBAL#product#security-hub","name":"AWS Security Hub","namespaceId":"GLOBAL#product","description":"AWS Security Hub","metadata":{}},{"id":"GLOBAL#pattern#use-cases","name":"Use Cases","namespaceId":"GLOBAL#pattern","description":"Use Cases","metadata":{}}]}},{"fields":{"useCaseTitle":"Visualize your security findings to discover new insights","id":"product-use-cases#usecase-4-prod-overview-awssecurityhub","customSortOrder":"4","useCaseSummary":"

Better prioritize the response and remediation efforts of your central security teams and DevSecOps teams by searching, correlating, and aggregating, fine-tuning diverse security findings by accounts and resources as well as visualizing findings in the Security Hub dashboard."},"metadata":{"tags":[{"id":"GLOBAL#product#security-hub","name":"AWS Security Hub","namespaceId":"GLOBAL#product","description":"AWS Security Hub","metadata":{}},{"id":"GLOBAL#pattern#use-cases","name":"Use Cases","namespaceId":"GLOBAL#pattern","description":"Use Cases","metadata":{}}]}},{"fields":{"patternHeading":"Use cases","id":"product-use-cases#usecase-heading-prod-overview-awssecurityhub"},"metadata":{"tags":[{"id":"GLOBAL#pattern#pattern-data","name":"pattern-data","namespaceId":"GLOBAL#pattern","description":"pattern-data","metadata":{}},{"id":"GLOBAL#product#security-hub","name":"AWS Security Hub","namespaceId":"GLOBAL#product","description":"AWS Security Hub","metadata":{}},{"id":"GLOBAL#pattern#use-cases","name":"Use Cases","namespaceId":"GLOBAL#pattern","description":"Use Cases","metadata":{}}]}}]},"metadata":{"auth":{},"pagination":{"empty":false,"present":true},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security-hub/"},"environment":{"stage":"prod","region":"us-east-1"},"sdkVersion":"1.0.120"},"refMap":{"manifest.js":"3daf852ae2","rt-qa-sampler.css":"6682628699","rt-qa-sampler.js":"68f95da020","rt-qa-sampler.css.js":"088fba180d","rt-qa-sampler.rtl.css":"ebe31daae4","rt-qa-sampler.rtl.css.js":"17e3041e3d"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","topic":"useCaseTitle","content":"useCaseSummary"}}}

Use cases

Automatically enrich findings, remediate them, or send them to ticketing systems with Security Hub’s integration with Amazon EventBridge.

Simplify and streamline data ingestion into your Security Information and Event Management (SIEM), ticketing, and other tools by consolidating the integrations between AWS services and your downstream tooling and by normalizing your findings.

Better prioritize the response and remediation efforts of your central security teams and DevSecOps teams by searching, correlating, and aggregating, fine-tuning diverse security findings by accounts and resources as well as visualizing findings in the Security Hub dashboard.